CVE-2026-18658: IBM Operational Decision Manager

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.

Affected products

  • IBM Operational Decision Manager: version 9.6.0.0 only; version 9.5.0.0 only; version 8.11.1.0 only; version 8.11.0.1 only; version 8.12.0.1 only; version 9.5.0.1 only; …

Published 2026-09-04. Last modified 2026-09-10.